Known vulnerabilities in docker (Alpine package)

Software CPE: cpe:2.3:o:alpine:docker_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 11
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting docker (Alpine package) docker (Alpine package) is affected by 11 known vulnerabilities: 9 medium, 2 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50273 - Permissions, Privileges, and Access Controls
CVE-2021-21284
CWE-264 Medium
No
No
20.10.3-r0 02.02.2021 SB2021020305
SB2021020611
SB2021020922
and 9 more
#VU50274 - Resource exhaustion
CVE-2021-21285
CWE-400 Medium
No
No
20.10.3-r0 02.02.2021 SB2021020305
SB2021020611
SB2021020923
and 9 more
#VU48795 - Improper Access Control
CVE-2020-15257
CWE-284 Medium
Available
No
19.03.14-r0 01.12.2020 SB2020120606
SB2020120609
SB2020120715
and 10 more
#VU28556 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2020-13401
CWE-451 Medium
Available
No
19.03.11-r0 03.06.2020 SB2020060335
SB2020060336
SB2020062305
and 7 more
#VU20969 - Uncontrolled Search Path Element
CVE-2019-14271
CWE-427 Medium
Available
No
19.03.1-r1 10.09.2019 SB2019091012
SB2019072625
SB2023051608
#VU20501 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-15664
CWE-22 Low
No
No
18.09.7-r0 02.09.2019 SB2019090205
SB2019062523
SB2019072507
and 3 more
#VU19390 - Information Exposure Through Log Files
CVE-2019-13509
CWE-532 Medium
No
No
18.09.8-r0 26.07.2019 SB2019091012
SB2019110702
SB2019121201
and 7 more
#VU12804 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2016-9962
CWE-362 Low
No
No
1.12.6-r0 17.05.2018 SB2018051723
SB2017011305
SB2017011218
and 13 more
#VU32459 - Permissions, Privileges, and Access Controls
CVE-2014-6408
CWE-264 Medium
No
No
1.4.1-r0 12.12.2014 SB2014121205
SB2015012609
SB2014112502
and 2 more
#VU32458 - Improper Link Resolution Before File Access ('Link Following')
CVE-2014-6407
CWE-59 Medium
No
No
1.4.1-r0 12.12.2014 SB2014121204
SB2015012608
SB2014112502
and 2 more
#VU33063 - Command injection
CVE-2014-8990
CWE-77 Medium
No
No
1.12.6-r0 05.12.2014 SB2017011016
SB2017011019
SB2015012304
and 7 more